ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 9 - 5V0-35.21 discussion

Report
Export

An administrator has deployed vRealize Operations and has been tasked with ensuring that the VMware SDDC remains compliant to the VMware vSphere Security Configuration Guide. The compliance benchmark is showing that the VMware SDDC is less than 10% compliant to the standards.

Which three configuration options could have triggered a compliance alert? (Choose three.)

A.
The MAC Address Changes policy is set to reject on a Distributed Port Group.
Answers
A.
The MAC Address Changes policy is set to reject on a Distributed Port Group.
B.
NTP is enabled and confiqured on a vSphere ESXi host.
Answers
B.
NTP is enabled and confiqured on a vSphere ESXi host.
C.
SSH is enabled and confiqured on a vSphere ESXi host.
Answers
C.
SSH is enabled and confiqured on a vSphere ESXi host.
D.
A Floppy drive is connected to a virtual machine.
Answers
D.
A Floppy drive is connected to a virtual machine.
E.
Transparent Page Sharing is Disabled on a virtual machine.
Answers
E.
Transparent Page Sharing is Disabled on a virtual machine.
F.
The Promiscuous Mode policy is set to allow on a Distributed Port Group.
Answers
F.
The Promiscuous Mode policy is set to allow on a Distributed Port Group.
Suggested answer: C, D, F

Explanation:

SSH enabled on an ESXi host (Option C) can be a security concern if not properly managed, as it can provide broad access to the host.

A connected Floppy drive (Option D) can be a risk as it could be used to introduce unauthorized data or software into the VM.

Allowing Promiscuous Mode (Option F) on a Distributed Port Group can be a security risk as it allows all virtual machines connected to the port group to see all network traffic, which is generally not recommended in secure environments.

asked 16/09/2024
shikeba barakzei
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first